
Events Calendar For Divi Security & Risk Analysis
wordpress.org/plugins/event-manager-for-diviRevolutionize event pages with Events Calendar For Divi. Elevate design and engage visitors effortlessly.
Is Events Calendar For Divi Safe to Use in 2026?
Generally Safe
Score 100/100Events Calendar For Divi has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The event-manager-for-divi plugin, version 5.0.2, exhibits a mixed security posture. On the positive side, the plugin demonstrates good practices by exclusively using prepared statements for SQL queries and performing a high percentage of output escaping. It also has no recorded vulnerabilities (CVEs) and no known critical or high-severity taint flows, which is a strong indicator of developer attention to secure coding. The absence of file operations and external HTTP requests further reduces potential attack vectors.
However, there are significant concerns. The plugin exposes one REST API route without any permission callbacks, creating a direct entry point into the application that is not protected by authentication or authorization checks. This unprotected entry point, coupled with the absence of nonce checks and capability checks across the board, presents a notable risk. While the code signals don't indicate dangerous functions or unsanitized paths in taint analysis, the lack of proper authentication on the REST API route is a critical oversight that could potentially be exploited if the route handles any user-supplied input or performs sensitive actions.
In conclusion, while the plugin benefits from solid database and output handling, the single unprotected REST API route is a significant weakness. The lack of any recorded vulnerabilities in its history is positive, but it does not negate the immediate risk posed by the identifiable unprotected entry point. Developers should prioritize addressing the missing permission callbacks for the REST API route to enhance the plugin's overall security.
Key Concerns
- REST API route without permission callbacks
- No nonce checks
- No capability checks
- Bundled Freemius v1.0 library
Events Calendar For Divi Security Vulnerabilities
Events Calendar For Divi Code Analysis
Bundled Libraries
Output Escaping
Events Calendar For Divi Attack Surface
REST API Routes 1
WordPress Hooks 8
Maintenance & Trust
Events Calendar For Divi Maintenance & Trust
Maintenance Signals
Community Trust
Events Calendar For Divi Alternatives
Events Calendar Modules for Divi
events-calendar-modules-for-divi
Integrate The Events Calendar with Divi Theme and use Divi event calendar modules to design and display event listings easily inside Divi Builder.
Supreme Modules Lite – Divi Theme, Extra Theme and Divi Builder
supreme-modules-for-divi
Divi Supreme lite plugin enhances the experience and features found on Divi and extend with custom creative modules to help you build amazing websites …
Popups for Divi
popups-for-divi
A quick and easy way to create Popup layers inside the Divi Visual Builder!
Column Shortcodes
column-shortcodes
Adds shortcodes to easily create columns in your posts or pages.
Divi Torque Lite – Divi Theme, Divi Builder & Extra Theme
addons-for-divi
The Divi Torque plugin you install after Divi builder! Packed with 70+ stunning modules like Post Grid, Filterable Gallery, Google Reviews, and more.
Events Calendar For Divi Developer Profile
15 plugins · 6K total installs
How We Detect Events Calendar For Divi
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/event-manager-for-divi/assets/css/event-manager-for-divi.css/wp-content/plugins/event-manager-for-divi/assets/js/event-manager-for-divi.js/wp-content/plugins/event-manager-for-divi/assets/js/event-manager-for-divi.jsevent-manager-for-divi/assets/css/event-manager-for-divi.css?ver=event-manager-for-divi/assets/js/event-manager-for-divi.js?ver=HTML / DOM Fingerprints
et_fb_wpt_event_content/wp-json/wpt-events/v1/events/